Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

11–20 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#11
post #10

I use one of these tokens for work. Spying is one thing but destroying encryption is another evil thing to do. If the NSA has introduced bugs in crypto then who's to say someone else can exploit the same crypto.

I don't think this fiasco is related to the tokens but yes the tokens has other problems such that it didn't need NSA to break it.

Re: Secret contract tied NSA and security industry pioneer

#12
post #6

The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

Re: Secret contract tied NSA and security industry pioneer

#13
post #3

TLDR: "RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit." Dual_EC_DRBG was a NIST standard.

More specifically, it was RSA's "BSAFE" product which is problematic and was paid to be a default.

Re: Secret contract tied NSA and security industry pioneer

#14
post #2

Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.

No, it sounds like no product from any American company can be trusted as long as the current regime is in place.

At least that's the message that comes through loud and clear in the rest of the world.

Re: Secret contract tied NSA and security industry pioneer

#15
From the BSAFE product page:

"RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts." [emphasis added]

Re: Secret contract tied NSA and security industry pioneer

#18
post #6

The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…

Maybe the 10M carrot came with even a bigger stick

Re: Secret contract tied NSA and security industry pioneer

#20
I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly discredited through an otherwise seemingly unrelated matter in the future, you should always remember that I have made this public statement."
Post reply on HN